All versions of Hangzhou Xiongmai Technology Co., Ltd XMeye P2P Cloud Server may allow an attacker to use an undocumented user account "default" with its default password to login to XMeye and access/view video streams.
References
Link | Resource |
---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-18-282-06 | Third Party Advisory US Government Resource |
Configurations
Information
Published : 2018-10-10 08:29
Updated : 2019-10-09 16:37
NVD link : CVE-2018-17919
Mitre link : CVE-2018-17919
JSON object : View
CWE
CWE-798
Use of Hard-coded Credentials
Products Affected
xiongmaitech
- xmeye_p2p_cloud_server